Design Case Study

Campus Floor Connectivity Design

CCDE Mindset Campus Design Cisco Switching SD-WAN Zone Fiber Connectivity

Enterprise building-to-building campus design using FortiGate 600-series firewalls in HA, Cisco C9300 StackWise, Cisco C9500 StackWise Virtual, OM3 multimode fiber, access zones, segmentation, and clear operational handoff.

Asteria campus connectivity design diagram
Enterprise campus design for Asteria Operations Group, showing Building 1 WAN handoff, ISP service links into Cisco C9300 StackWise, FortiGate 600 HA in an SD-WAN zone, Building 2 C9500 StackWise Virtual core, OM3 multimode fiber, Floor 5 OM3 fiber rack, C9300 access zones, and generic ISP handoffs.

On This Design

Design Context

The scenario was a building-to-building campus connectivity design. Building 1 handled the WAN handoff: ISP service links land on the Cisco C9300 StackWise block, the SD-WAN zone connects into the FortiGate 600-series HA firewall pair, and the C9300 feeds the Building 1 OM3 fiber rack. Building 2 hosted the campus core on Floor 1 using two Cisco C9500 switches in StackWise Virtual, with an OM3 fiber rack extending toward Floor 5 access zones and a local Floor 1 extension area.

I remember putting a lot of care into this design because it was not just about "connecting switches." The real work was defining the physical fiber path, the security handoff, the campus core role, the Floor 5 access distribution model, and the operational documentation that would make troubleshooting easier later.

Hardware Inventory and Roles

This section is only the logical role view. It maps each layer to its platform and operational responsibility without trying to behave like a procurement list or a cable schedule. The goal is to make the architecture readable before getting into exact part numbers.

Layer / Role Recommended Platform Quantity Purpose Reference
Building 1 SD-WAN Zone FortiGate 600-series HA pair 2 firewalls Firewall policy, SD-WAN services, Internet security boundary, and controlled routing into the campus. FortiGate 600F
Building 1 WAN Aggregation Cisco Catalyst C9300 StackWise Stacked switch block Receives ISP/WAN service handoffs, connects to the FortiGate HA pair, and forwards toward the Building 1 OM3 fiber rack. Cisco C9300
Building 2 Floor 1 Core 2 x Cisco Catalyst C9500 in StackWise Virtual 2 switches Campus core/distribution point, receiving Building 1 OM3 fiber and extending OM3 fiber through the Floor 1 OM3 fiber rack to Floor 5. Cisco C9500 / StackWise Virtual
Building 2 Floor 1 OM3 Fiber Rack OM3 fiber rack Fiber handoff point Clean demarcation between the C9500 core and the OM3 runs toward Floor 5 and local extensions. Cisco 10G optics
Building 2 Floor 5 OM3 Fiber Rack OM3 fiber rack Fiber handoff point Receives OM3 fiber from Floor 1 and presents clear handoffs into the D1, D2, and D3 access zones. Cisco 10G optics
Building 2 Floor 5 Access Cisco Catalyst C9300 access switching with StackWise groups D1, D2, D3 zones Each zone has 8 access switches, split into two 4-switch StackWise groups. Cisco C9300
Building 2 Floor 1 Extension 4 x Cisco Catalyst C9300 in StackWise 1 stack Local Floor 1 C9300 extension connected from the C9500 core area through OM3 multimode fiber. Cisco C9300

Detailed Material Reference

This section is intentionally closer to a BOM/procurement view. It documents specific part numbers, licensing families, optics, network modules, and future capacity items without re-explaining the full architecture.

Area Specific Item Quantity Design Use Reference
Access switching C9200L-48P-4G PoE access switches with redundant power design, Network Essentials (C9200L-NW-E-48), and DNA Essentials (C9200L-DNA-E-48). 16 switches Floor access layer for endpoint connectivity, PoE endpoints, phones, APs, cameras, and access-control systems. Cisco C9200L
Access Ethernet handoff GLC-TE 10/100/1000BASE-T SFP transceivers. 6 transceivers Copper Ethernet SFP handoffs where a 1G RJ-45 presentation is required. Cisco 1G SFPs
Distribution switching C9300-24UX, 24-port Multigigabit Cisco UPOE (10G/5G/2.5G/1G/100M), StackWise and StackPower cables, redundant power supplies, Network Advantage, and DNA Advantage. 6 switches Distribution/access aggregation layer with multigigabit capacity and stack-based operational simplicity. Cisco C9300
Distribution 1G uplinks C9300-NM-4G 4x1G uplink modules. 6 modules 1G SFP uplink capacity for distribution uplinks and fiber handoffs. C9300 network modules
1G inter-building optics GLC-LH-SMD 1Gbps 1000BASE-LX/LH 10 km 1310 nm SFP transceivers. 4 transceivers 1G optical links between the expansion floor and the adjacent anonymized building path, documented here as Building Orion to Building Atlas. GLC-LH-SMD
Future capacity C9300-NM-8X 8x10G uplink modules and SFP-10G-LR 10GBASE-LR SFP+ optics. 2 modules / 4 optics Future 10G uplink growth path if the access/distribution layer requires more capacity. C9300-NM-8X / SFP-10G-LR

Switch Port and Uplink Plan

A design document should make it clear which ports are access-facing, which ports are uplinks, which links are handoffs, and where demarcation happens. This section is about port roles and operational boundaries, not platform selection or optic inventory.

Device Role Port Role Port Type Design Use Reference
Floor 5 D1/D2/D3 access zones Access ports Cisco C9300 access switch copper ports User endpoints, IP phones, APs, cameras, badge readers, and local endpoint access. Cisco C9300
Floor 5 D1/D2/D3 access zones Stack ports StackWise groups Each zone is documented as 8 switches total, split into two 4-switch stacks for operational separation. C9300 StackWise
Building 2 C9500 core Floor 5 fiber-rack uplinks OM3 multimode fiber A single OM3 fiber run from the Floor 1 OM3 fiber rack toward the Floor 5 OM3 fiber rack, feeding D1/D2/D3. Cisco optics
Building 2 Floor 1 extension Extension uplink OM3 multimode fiber Connects the Floor 1 C9300 four-switch StackWise extension to the Floor 1 core area. Cisco optics
Building 1 C9300 StackWise ISP and FortiGate handoff Fiber and routed firewall handoff Receives ISP/WAN service handoffs, connects to the FortiGate HA pair, and forwards toward the Building 1 OM3 fiber rack. VLAN trunks / LACP
Building 1 OM3 Fiber Rack Inter-building handoff Fiber patching Connects Building 1 toward Building 2 Floor 1 core/distribution. Optics compatibility

Specific Uplink and Optic Notes

This section stays focused on media, modules, and distance assumptions. I would keep these optics documented directly in the design notes so implementation and procurement do not have to infer the physical layer from the topology diagram.

Use Case Component Quantity Technical Note Reference
1G fiber link between anonymized buildings GLC-LH-SMD 4 1000BASE-LX/LH, 1310 nm, up to 10 km, used for 1 Gbps optical handoffs between the expansion floor and the adjacent building path. Cisco 1G SFPs
Distribution 1G uplink module C9300-NM-4G 2 baseline / 6 full distribution set 4x1G uplink module for C9300-based distribution switching. C9300 modules
Access copper SFP handoff GLC-TE 6 10/100/1000BASE-T SFP for copper Ethernet presentation. Cisco 1G SFPs
Future 10G distribution uplinks C9300-NM-8X + SFP-10G-LR 2 modules / 4 optics Future-ready 8x10G uplink module with 10GBASE-LR optics for higher-capacity uplinks. C9300-NM-8X / 10G SFP+

Design Requirements

Capacity

Support current users while leaving room for future seats, wireless, cameras, and access systems.

growth ready

Resiliency

Use redundant switching, fiber paths, power planning, and logical bundling where possible.

no easy SPOF

Security

Preserve segmentation and use access controls suitable for enterprise operations.

least exposure

Operations

Keep the design readable for support teams, audits, troubleshooting, and future changes.

clear handoff

Connectivity Options

This section is about alternatives and trade-offs, not the final topology. The main decision was how much separation to keep between WAN handoff, firewall policy, distribution, and building-to-building fiber.

The final flow is explained later in the proposed architecture. Here, the useful part is showing why each option was attractive and what operational cost it introduced.

Option Strength Trade-off
Direct WAN aggregation into campus distribution Simple physical design and fewer intermediate devices. Can blur the boundary between WAN services, firewall policy, and campus distribution.
Dedicated WAN aggregation stack before firewall/distribution Cleaner demarcation for ISP VLANs, Port-Channels, firewall zones, and troubleshooting. Adds hardware and makes documentation discipline more important.
Single OM3 run from Floor 1 to Floor 5 access rack Clear and easy to document when the path is known and controlled. Requires strong rack labeling and future planning if capacity grows.

Proposed Architecture

This is the final integrated view of the design. After separating roles, procurement details, port demarcation, optics, and options, this section ties the actual traffic and physical flow together.

The architecture starts in Building 1, where ISP/WAN service handoffs land on the Cisco C9300 StackWise block. The FortiGate 600-series HA pair connects to that aggregation layer to provide firewall, SD-WAN, and security policy. The same C9300 block feeds the Building 1 OM3 fiber rack, and from there the inter-building fiber path reaches Building 2 Floor 1.

From the Building 2 Floor 1 core, OM3 multimode fiber runs through a Floor 1 OM3 fiber rack toward the Floor 5 OM3 fiber rack. Floor 5 is divided into three Cisco C9300 access zones: D1, D2, and D3. Each zone contains 8 access switches, split into two 4-switch StackWise groups. A separate Floor 1 extension also uses OM3 multimode fiber and terminates into a 4-switch Cisco C9300 StackWise block.

Transceiver and Media Plan

This section is not a second BOM. It captures physical media assumptions: fiber type, distance validation, patching path, and the module family that should be confirmed before implementation.

Use Case Module / Optic Media Notes
Building 1 to Building 2 handoff Distance-dependent fiber optic Fiber between racks Validate distance and facilities path before choosing final optic type.
Building 2 Floor 1 to Floor 5 OM3 fiber rack 10G-capable multimode optic OM3 multimode fiber A single OM3 fiber run feeds the Floor 5 OM3 fiber rack before handoff to the access zones.
Floor 1 extension 10G-capable multimode optic OM3 multimode fiber Connects the Floor 1 core area to the 4-switch C9300 StackWise extension.
C9300 / access uplinks C9300 uplink modules as required Fiber or copper depending endpoint Module choice depends on port density, required speed, and optic plan.
FortiGate to C9300 handoff Routed firewall handoff Fiber or copper based on interface availability Keep firewall inside/outside roles clearly documented for operations.

Resiliency Decisions

  • Use FortiGate 600-series HA inside the SD-WAN zone for firewall and policy control.
  • Use Cisco C9300 StackWise in Building 1 for ISP, FortiGate, and fiber-rack aggregation.
  • Use two Cisco C9500 switches in StackWise Virtual as the Building 2 Floor 1 core.
  • Use a clean OM3 fiber handoff between Building 2 Floor 1 and Floor 5 racks.
  • Split Floor 5 Cisco C9300 zones into two 4-switch StackWise groups per zone for operational clarity.
  • Document fiber endpoints clearly so troubleshooting starts with facts, not guessing.

Security and Layer 2 Controls

The original design included security controls that are still important in enterprise access networks: 802.1X for access control, VLAN segmentation, ACLs for traffic filtering, storm control, PortFast, and BPDU Guard. These are not flashy features, but they protect the network from common access-layer problems.

  • 802.1X for authenticated access.
  • VLAN segmentation for user, voice, management, cameras, and access systems.
  • Storm control for broadcast protection.
  • PortFast for endpoint access ports.
  • BPDU Guard to protect the spanning-tree edge.
  • ACLs for controlled inter-segment access.

Growth Planning

One of the strongest parts of this design is that it was not only built for the day-one requirement. It considered future users, wireless expansion, security cameras, access control systems, and additional structured cabling needs. A floor expansion should not be designed only for the first wave of endpoints; it should be designed for the next operational cycle.

Lessons Learned

  • A good design is not just a diagram; it is a set of operational decisions.
  • Fiber paths, rack locations, and power planning are part of network resiliency.
  • Access-layer security should be designed from the beginning, not added later.
  • Design options should show trade-offs, not just a preferred answer.
  • Anonymizing old work is a good way to document experience without exposing customer data.

Design Improvement I Would Apply Today

Looking at this design with more experience, I would prefer to land the ISP handoffs on a dedicated switch stack first, then connect that stack toward the distribution layer. That would keep the WAN side cleaner, allow the ISP circuits to be carried with tagged VLANs, and give the firewall a more deterministic handoff model.

In that model, each FortiGate would receive redundant LACP trunks from the distribution switches. I would separate the Port-Channels by function: one Port-Channel for WAN-side VLANs and another Port-Channel for LAN-side/internal VLANs. The VLAN IDs on the firewall would match the VLANs created on the Cisco distribution layer, keeping the relationship between firewall zones and switch segmentation easy to operate.

For example, I would reserve multiple physical links per firewall, such as 8 ports to the first FortiGate and 8 ports to the second FortiGate, bundled with LACP. The goal is not only bandwidth; it is operational redundancy, predictable failure behavior, and a clean separation between WAN and LAN roles.

ExampleWAN-side Port-Channel toward FortiGate
interface range TenGigabitEthernet1/0/1-8
 description FortigateFW-601-E-to-WAN
 switchport mode trunk
 channel-protocol lacp
 channel-group 101 mode active

interface Port-channel101
 description FortigateFW-601-E-to-WAN
 switchport mode trunk
 switchport trunk allowed vlan <wan-vlan-list>
Looking back, I like this design because it reminds me that network architecture is a balance between physical reality, business growth, security, and the people who will operate the network after the deployment is finished.

Comments & Discussion

Notes, improvements, and design trade-off comments are welcome.